WinRAR has patched CVE-2025-8088, a path traversal bug actively exploited by Russia-linked RomCom to target financial, defense, manufacturing, and logistics firms in Europe and Canada. The flaw allows code execution via crafted archives; defenders should urgently update to the latest WinRAR release and treat untrusted archives as executable content while hunting for exploitation artifacts.
Source: SecurityWeek
Over 29,000 Microsoft Exchange servers remain unpatched for high-severity flaw
More than 29,000 internet-exposed Exchange servers have not been updated against a high-severity vulnerability that enables lateral movement into Microsoft cloud environments and can culminate in full domain compromise. Organizations should prioritize patching, reduce exposure of on-prem mail infrastructure, and enforce least-privilege, conditional access, and segmentation to limit blast radius.
Source: BleepingComputer
BadCam: Lenovo webcams can be turned into persistent BadUSB devices
Eclypsium researchers detailed “BadCam,” showing how flaws in certain Linux-based Lenovo webcams allow attackers to reprogram them as BadUSB/HID devices that inject keystrokes and persist across reboots. While the demo focused on Lenovo models, similar devices may be at risk; mitigate by applying firmware updates, restricting USB HID trust, and enforcing device control policies.
Source: SecurityWeek
Google confirms Salesforce CRM breach tied to Google Ads prospects; extortion demand issued
Google disclosed that a Salesforce CRM instance used for prospective Google Ads customers was breached, and the attackers have issued an extortion demand. Although current indications point to prospects’ data rather than core Google systems, the incident raises phishing and social-engineering risks for affected orgs; monitor for targeted fraud using Ads-related details.
Source: Security Affairs
Trend Micro Apex One on-prem critical 0-day exploited; workaround available, no patch yet
A critical vulnerability in Trend Micro’s on-prem Apex One endpoint security management console is under active exploitation, and no patch is available at this time. Organizations should immediately apply the vendor’s workaround, remove public exposure of the console, enforce MFA and network ACLs, and monitor for lateral movement and suspicious admin actions.
Source: The Register
Malicious Google Calendar invites could hijack Gemini agents to leak user data
Google fixed a vulnerability where specially crafted Calendar invites could remotely take over Gemini agents running on a user’s device, enabling sensitive data exfiltration. Limit agent permissions to only necessary connectors, be cautious with unsolicited calendar invites, and ensure apps are updated to versions containing Google’s fix.
Source: BleepingComputer
‘Win-DDoS’ shows how public domain controllers can be weaponized for massive DDoS
SafeBreach researchers unveiled “Win-DDoS,” a technique that abuses RPC and LDAP to conscript public-facing Windows domain controllers into a DDoS botnet. Keep DCs off the public internet, filter RPC/LDAP at the perimeter, and monitor for anomalous service traffic to reduce exposure to this emerging attack vector.
Source: The Hacker News
You May Also Be Interested In...
Security flaws in a carmaker’s web portal let one hacker remotely unlock cars from anywhere
Smart buses flaws expose vehicles to tracking, control, and spying